Skip to content
Conference

FSED: A Feature-Space Ensemble Defense for Detecting Adversarial Examples

Sep 2026 · 2026 IEEE International Conference on Advanced Telecommunication and Networking Technologies (ATNT) · pp. 134-137 · 0 citations · 21 references

Abstract

This paper introduces a Feature-Space Ensemble Defense (FSED) framework, which involves adversarial training, joint confidence calibration, and class-conditional Mahalanobis feature-space anomaly scoring to facilitate powerful adversarial detection. The proposed method considers the final-layer uncertainty. It also models the clean latent feature manifold and marks the inputs that are out of distribution from it. The experiments cover CIFAR-10 and cross-dataset experiments on Fashion-MNIST, under FGSM, PGD (ϵ=0.1 and ϵ=8/255), and C&W, reporting mean ± std over three seeds. They demonstrate that the feature-space anomaly signal is more discriminative and transferable than the confidence at the output level. Its AUROC reaches 1.00, whereas confidence falls to 0.11 under PGD. With the false-positive budget fixed at 10%, FSED flags 96–99.8% of the FGSM and PGD attacks on CIFAR-10, compared with under 10% for output confidence. A component- and rule-level ablation isolates what each part contributes and maps the detection–false-alarm trade-off. The results show the viability of internal representation monitoring for more reliable adversarial defense of CNN-based image classification.

View source

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.